decrypted · 10 october 2026 · vulnerabilities and patching · ai and llm security · surveillance and privacy
One person, nine banks: AI agents change the arithmetic of attack
On 5 October Decrypted covered seven Korean lenders breached through side doors, with an AI tool suspected. That suspicion has now hardened into evidence. CrowdStrike says one probably Chinese-speaking, financially motivated individual used an open-source AI penetration-testing agent called ARTEX, alongside commercial language models including Anthropic's Claude, against South Korean banks. Reuters reports at least nine have disclosed, or been reported as targets of, attacks since late September. The lesson for UK boards is not the novelty of the tool. It is the arithmetic: one person, many targets.
What CrowdStrike found
ARTEX was published on GitHub this year by a developer using the handle "Autumn". It is not a model in itself. It is a harness that connects to outside models such as Claude, ChatGPT and DeepSeek and lets them work through the steps of a penetration test. Its own page says it is for learning and local verification, not for testing live systems. Think of a locksmith's apprentice who never tires: point it at a street of front doors and it tries each handle, reads what it learns and decides what to try next.
CrowdStrike reached its conclusion by analysing AI coding-tool sessions and infrastructure tied to the campaign. BleepingComputer reports that the attacker's servers held open directories containing Claude Code session histories and configuration files, which is a rather careless way to run a crime. In one session the actor asked Claude to write a security researcher's CV that included a Telegram account and a location in Maoming, China. CrowdStrike says this likely belongs to the attacker, though the researchers judged the personal details too unreliable to confirm anyone's identity.
What the banks lost
Shinhan Bank said about 25,000 customers' personal information was compromised, and KB Kookmin Bank said 119. BleepingComputer reports exposed card data and outages at some banks. South Korean police have opened an investigation. Public reporting has not tied every affected bank to this one actor, so read "nine" as a campaign window, not a proven single operation.
The Secure by Design reading
CrowdStrike's Adam Meyers said the approach "allows one human to target many customers in a very short period of time". Attacker effort used to scale with attacker hours. Now it scales with API credit. Any organisation that relied on being too small or too dull to be worth the effort has lost that protection.
The answers are unglamorous, and they are design decisions, not products:
- Know your front doors. Keep a live inventory of every internet-facing service, including forgotten supplier portals and enquiry forms. An agent will find the one you forgot.
- Make the first foothold worthless. Segment networks and limit what any one service account can read, so that card and personal data do not sit within reach of a front-end system.
- Watch for machine tempo. Rate limits and alerts on rapid, sequential probing catch an agent's rhythm, which differs from a human's.
- Write detection into supplier contracts. Ask in advance how a supplier would notice and tell you, not afterwards.
The cost is mostly discipline and inventory work, and it is the part no vendor can do for you. Nor will closing the source help: the ARTEX developer has reportedly done exactly that, but BleepingComputer says English and Korean derivatives already exist. The tool is out.
Also this week
SonicWall SMA1000, again. SonicWall's notice SNWLID-2026-0017 rates CVE-2026-102255 at CVSS 10.0 and lists fixes at 12.4.3-03670 or 12.5.0-03082 and higher. SonicWall says there is no evidence of exploitation in the wild. BleepingComputer reports that Previdian's honeypots have logged attempts consistent with the flaw, aimed at an internal database service, and Previdian has not established whether any succeeded. Shadowserver tracks more than 400 exposed appliances. The same WorkPlace interface was hit by earlier flaws in July and September, and BleepingComputer notes that CISA has added 19 SonicWall vulnerabilities to its catalogue over four years, 13 of them flagged as used by ransomware gangs. If you run one, patch, and ask why a remote-access gateway can still be talked into making requests on an attacker's behalf.
Windows Update certificates expire in 2027. Microsoft says the certificates Windows uses to trust Windows Update expire on 17 May 2027 and 19 June 2027, and that devices on unsupported Windows versions will lose access to Windows Update. Replacement certificates have already been delivered through security updates, and Windows 11 25H2 and later need no action. Windows 10 and other supported Windows 11 versions need the July 2026 security update or later before 19 June 2027, while Windows Server 2016 and 2019 need it before 17 May 2027. Microsoft says the change does not apply to devices fed by WSUS. The design lesson is dull and valuable: every trust anchor has a clock, and the estate you cannot patch runs out of road first.
Sources
- BleepingComputer: ARTEX AI, Claude agents used in cyberattacks on South Korean banks
- Taipei Times: S Korean banks likely hacked by China-based actor, CrowdStrike
- SonicWall: SMA 1000 Series affected by Multiple Vulnerabilities (SNWLID-2026-0017)
- BleepingComputer: Max severity SonicWall SMA1000 flaw now exploited in attacks
- Microsoft Message Center MC1491763: Prepare for Windows Update certificate rotation in 2027
- BleepingComputer: Microsoft says outdated Windows devices will lose security protection next year
If you want help finding your front doors before an agent does, get in touch.
More like this
- A Zammad zero-day chain let an AI agent breach the people who find zero-days 1 october 2026
- A Russian spy operation had Claude rewrite its own malware after getting caught 13 september 2026
- A Beijing contractor ran the hacking kit, and the doors it used were a decade old 9 october 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.